Decorative page background

Smart glasses in the workplace: A new aid, or a new GDPR risk?

Smart glasses in the workplace: A new aid, or a new GDPR risk?

Smart glasses are no longer a mere technological curiosity. The less conspicuous they appear, the more legal issues they raise – particularly in the workplace. A recent decision by the Catalan data protection authority, APDCAT, shows that even if it cannot be proven that recording has actually taken place using smart glasses, employers still have obligations they must fulfil.

Just because nobody can prove anything, that doesn’t mean the problem is over

The Catalan supervisory authority APDCAT[1] dealt with a complaint lodged by a bus driver against the transport company Transports de Barcelona. According to the complaint, another employee of the same employer was alleged to have used private smart sunglasses with a built-in camera while performing control duties, connected via Bluetooth to a mobile phone, and, without the knowledge of the persons concerned, made video and audio recordings inside the bus.

The employer stated that it did not provide employees with any such devices, that such equipment was not part of the company’s tools, and that there was no internal protocol authorising the use of such devices for inspection or supervision purposes. APDCAT ultimately dismissed the complaint because the covert recording itself had not been proven and there was insufficient evidence to initiate sanctioning proceedings.

But that is not the end of the decision’s significance. APDCAT expressly noted that the recording of images or voice by an employee in the workplace through a private device may, in certain circumstances, constitute processing that is not compliant with the GDPR. At the same time, it also observed that wearable devices, such as camera glasses, can capture not only images and audio, but also location data or biometric data.

Why are smart glasses unique from a privacy perspective?

Unlike a mobile phone, smart glasses are considerably less conspicuous. People nearby often cannot tell whether the device is active or whether it is recording. And this is a problem that supervisory authorities across Europe[2] and in non-European G7 countries have repeatedly highlighted: people lack a basic visual indication that they are being recorded. They cannot adapt their behaviour accordingly or exercise their rights.

In addition, the supervisory authorities are drawing attention to the scope of the data being collected. Smart glasses are not just a camera – they also use GPS, accelerometers and/or gyroscopes. Information about movement, behaviour or health can be derived from such data. All this without the person concerned even realising it.

The risks are even more pronounced in the workplace

The workplace is a sensitive environment. And smart glasses raise two sets of issues at once – that of the GDPR, and that of employment law. Is an employer even allowed to ban employees from bringing their private devices with cameras into work? Generally speaking, yes – as part of the legitimate management of the work process, an employer may lay down rules governing the use of devices in the workplace, including private devices. If an employee breaches this ban and, in doing so, processes the personal data of co-workers or customers, this may constitute grounds for termination of employment.

What if an employer wants to give smart glasses to employees – for example, for logistics or customer service? The situation is more complicated here. Compulsory wearing of devices that continuously record the surroundings and collect data on the employee themselves would have to be based on a solid legal foundation. It would be difficult to prove the employer’s legitimate interest in this context – in the vast majority of conceivable cases, the extent of the intrusion into the employee’s privacy would outweigh the employer’s interest. The employee’s consent could be considered, but there is always a risk that it will not be genuinely voluntary. Employees who do not wish to take part must not be disadvantaged – and if refusal were to have consequences under employment law, there could be no question of genuine consent.

At the same time, it cannot be overlooked that employees who wear such glasses are themselves data subjects. Data on their movements, performance, location or physiological parameters can be collected continuously and without the wearer being actively aware of it. These employees have full rights under the GDPR: the right to be informed about what data is being processed about them, for what purpose and for how long; the right to access and erase this data; and, should the data from the glasses be used for automated performance assessment, the right not to be subject to a decision based solely on automated processing.

The APDCAT decision further notes that the employer, as the controller of personal data, must have established rules and be able to demonstrate that it is effectively addressing the protection of personal data in the workplace – including in relation to the behaviour of its employees.

In practice, this entails, in particular:

  • clear internal rules on the use of private devices (not just smart glasses) in the workplace,
  • staff training,
  • the establishment of control mechanisms,
  • and a procedure for dealing with suspected covert recording.

It’s not just about making footage

A summary of the approaches taken by the supervisory authorities of the G7 countries, recently compiled by the French authority, shows that the issue of smart glasses goes beyond the question of whether someone has recorded someone else. These devices can continuously collect large amounts of data from sensors, and information about the user’s behaviour, health or other characteristics can be derived from this data.

The supervisory authorities therefore emphasise the principle of data minimisation. In addition, the issue of security also comes up time and again. Smart glasses are connected devices and, as such, represent a potential entry point for malware, data loss or unauthorised access to data.

What should employers address now?

Several practical conclusions can be drawn from both the APDCAT decision and the summary report by the G7 supervisory authorities.

If an employer does not wish to allow the use of private smart glasses in the workplace, they should specify this explicitly in their internal rules. If, on the other hand, they are considering the use of such glasses for work purposes, they must first determine the purpose of use, the scope of data collection, transparency towards employees and third parties, security, and the retention period.

It’s not just about rules on paper. Data protection must be carefully planned before you deploy the equipment – not only when a problem arises. Specifically, this means: the default setting should collect only the absolute minimum of data that is justified by the purpose and proportionate to that purpose; people in the vicinity should be informed whenever the device is active, and recording should be deactivated as soon as it is no longer required. And if, as an employer, you provide smart glasses to your employees, their use should be voluntary. Employees who do not wish to take part in such a scheme must not be disadvantaged.

What does that imply?

Smart glasses are not just another consumer electronics product. In the workplace, they blur the line between the private and professional spheres, between what is permissible and what is not – and they do so quietly, without any warning lights. It is still a new issue, but the regulators are keeping a close eye on it. The question is not whether this affects your company – but whether you have adequate rules in place governing the use of technology before someone comes to you with a complaint similar to the one recently raised in Barcelona.

If you are not sure how your company is doing in this regard – we would be happy to  take a look at it with you.

Related articles